RedactCheck

The last check before the pack goes out.

Drop in one document and see how much third-party personal data is still in it. Free, and the file will never be stored on my servers.

The problem

Getting a subject access request out the door isn’t the hard part. Deciding what to black out, and being able to say why, is.

A requester is entitled to a copy of their data, but that right doesn’t extend to information about other people. In UK practice that lands as Article 15(4) UK GDPR together with DPA 2018 Schedule 2, Part 3: the right to obtain a copy shall not adversely affect the rights and freedoms of others. What it means on a Tuesday afternoon is that somebody has to read every page and remove every other person’s name, address, phone number and offhand remark, then be ready to defend each of those calls.

So it gets done by hand. Highlight, check, black out, check again, and hope nothing was missed eight hundred pages in, because a name that slips through isn’t a typo. It’s a personal data breach with a 72-hour reporting clock attached.

And the question that follows a bad redaction isn’t “did you black it out?” It’s “why did you black that out, and not this?” A flattened black box has no answer, because it remembers nothing.

How it will work

  1. Drop in a PDF.

    It will render in your browser. The file itself won’t be uploaded to a server, and I won’t store it anywhere.

  2. The text gets checked for other people’s data.

    Only the extracted text will leave your machine, over an encrypted connection, to a detection service that flags personal data belonging to someone other than the requester. What comes back is a list and a set of coordinates: names, contact details, identifiers, and the passing mentions that are easiest to miss.

  3. You see the count before you decide anything.

    Example: “47 items of third-party personal data across 12 pages,” each one flagged by risk. Reading that report will be free and need no sign-up. One document per scan.

The scan is the free part. The work is the paid part. When you want the redaction actually done: it’s burned into the page rather than laid over it, you get the pack ready to send, and you get a decision log recording what was hidden and on what basis, with a draft rationale for each call that you review and confirm. A second pass over the finished pack comes later, so you can see what it turns up before the pack goes out. It will also say what it did not check: pages that arrived as images, handwriting, a name that only reads as a name in context.

Your files are never stored on my servers

Two separate promises live under that sentence, and they’re backed by different things, so I’ll keep them apart.

What the architecture guarantees

  • The document renders and gets redacted in your browser. The file doesn’t make the trip. There’s no bucket of customer documents to leak, because I never put one there.
  • Only extracted text leaves your machine, over an encrypted connection, for detection. Not the file itself.
  • Redactions are burned into the page. Not a black rectangle sitting on top of live text that anyone can drag away. That does mean redacted pages come back as images rather than searchable text — if that’s a problem for how you send packs out, tell me, because it changes what I build.
  • The free scan needs no account. Nothing to sign up for, and nothing to delete afterwards.

What a contract governs, not the architecture

  • Detection runs on a third-party AI service, which means the extracted text is processed by a sub-processor. The provider and its retention terms will be named on this page before anyone uploads anything real.
  • No SOC 2, no ISO 27001, no security questionnaires. Not yet, and I’d rather say so than imply otherwise.

Where the responsibility sits

  • This is a review aid, not a legal decision. It surfaces candidates and drafts the reasoning; you confirm what goes out, and responsibility for the final pack stays with you. The flow is being built so that you have to look at what it found before you can call it done.

Not built yet. Being built with the people who do this work.

RedactCheck is in development. If you handle subject access requests — in-house, freelance, or for clients — leave your email and I’ll send one note when the free scan is live. No newsletter and no drip sequence.

I’m Yunseon Hong, a sole developer, and the controller for the address you enter. I use it on the basis of your consent, for that one email, and share it with nobody. Unsubscribe in one click, or reply “stop”. The privacy notice has the rest.

Where your address goes, and for how long
  • Who receives it. Buttondown, LLC, 406 W Franklin St. #201, Richmond, VA 23221, United States.
  • Where it goes. The United States, on Heroku and Amazon Web Services.
  • When, and how. The moment you submit this form, over an encrypted connection.
  • What is sent. Your email address, and the dates you subscribed and confirmed. Nothing else.
  • What it is for, and for how long. To hold the list and send you one email when the scan is live. Kept until you unsubscribe, or 24 months from signup if the scan has not launched by then.
  • If you would rather not. Skip the form and write to im@redactcheck.com instead. I will tell you when it is live by hand, and nothing about that is worse for you.

Doing this by hand right now?

I’m talking to people who handle subject access requests, and it has nothing to do with signing up. I’d like to know how you deal with third-party redaction today — a couple of lines by email is plenty. Write to im@redactcheck.com.